Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Cannot reset the home page of IE11

  • Please log in to reply
7 replies to this topic

#1 ckw888


  • Members
  • 5 posts
  • Local time:12:48 PM

Posted 17 May 2015 - 02:09 PM

I tried to change the home page of my IE11 however it keeps on returned to some web site. Could someone suggest how to detect what keep reset the IE11 home page?

Edited by hamluis, 17 May 2015 - 04:04 PM.
Moved from Win 7 to Am I Infected - Hamluis.

BC AdBot (Login to Remove)



#2 ckw888

  • Topic Starter

  • Members
  • 5 posts
  • Local time:12:48 PM

Posted 17 May 2015 - 02:31 PM

After understanding my problem more, I found a temporary fix to disable the change of my IE11 home page.


The article is:


How To Lock Internet Explorer Home Page In Windows 8 | 7


However, I need to root the cause to find out who is the culprit. Please help.

#3 PuReinSAniTY


  • Members
  • 432 posts
  • Gender:Male
  • Location:in a basement
  • Local time:02:18 AM

Posted 17 May 2015 - 05:15 PM

hello, can you please provide more information, like what website you are getting redirected to?

they call me te java mayster

#4 ckw888

  • Topic Starter

  • Members
  • 5 posts
  • Local time:12:48 PM

Posted 17 May 2015 - 06:05 PM

The URL is http://www.2345.com/?16570.

#5 noknojon


  • Banned
  • 10,871 posts
  • Gender:Not Telling
  • Local time:02:48 AM

Posted 17 May 2015 - 07:13 PM

Open Internet Explorer > Go to the Tools icon at top Right side (Gear cog) > Go down to Internet Options > Delete the internet address you list above from the home page area > Type in your preferred Home Page.

I normally just use http://www.google.com/ or instead of google, type your own preferred home page. .....Press Apply > OK ....


Is this any help ??


While here, clean out any minor infections ..........


Please download RKill by Grinler to your desktop

  • If you have an old version, please delete it first
  • Right click on the new Red icon and select Run as Administrator
  • A black DOS box will appear for a short time and then disappear.
  • This is normal and indicates the tool ran successfully.
  • At most the tool will usually run for about 2 minutes
  • Please Copy and Paste the small log back here.

Do not reboot your computer until you complete the next step.

Now :

  • Download AdwCleaner by Xplode from Here or Here and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
     * Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button (only once)
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button only once for accuracy.
  • A report (AdwCleaner[R0].txt) will open in Notepad for your review.
  • Check the listed removals and see if you are OK with them.
  • If you have questions, post the Report log back here.
  • Click on the Clean button only once for accuracy
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK finally to allow AdwCleaner to Restart the computer and complete the removal process.
  • After rebooting, a log report (AdwCleaner[S0].txt) will open automatically.
  • **Copy and Paste the contents of that log in your next reply.**
  • To restore an item that has been deleted by accident : Open the program again,
  • Go to Tools (top left) > Quarantine Manager > check what you want restored > now click on Restore.

Note: With most Adware / Junkware / PUPs it is strongly recommended to deal with it like a legitimate program and uninstall from Programs and Features or Add/Remove Programs in the Control Panel.




If you already have a current version installed, Please update it
Please download Malwarebytes Anti-Malware

  • Follow the simple directions to install the program to desktop
  • Right click and choose "Run as administrator" to open Malwarebytes Anti-Malware and from the Dashboard please Check for Updates by clicking the Update Now... link
  • Open up Malwarebytes > Settings > Detection and Protection > Enable Scan for rootkit and Under Non Malware Protection set both PUP and PUM to Treat detections as malware.
  • Click on the SCAN button and run a Threat Scan with Malwarebytes Anti-Malware by clicking the Scan Now>> button.
  • If you find malware and tick it to remove it, you may be asked to re-boot the computer to finish cleaning.
  • Once completed please click on the History > Application Logs and find your scan log and open it and then click on the "copy to clipboard" button and post back the results on your next reply.


Please Copy and Paste those logs back here for review.


Thank You -

EDIT for Typo -

Edited by noknojon, 17 May 2015 - 07:14 PM.

#6 ckw888

  • Topic Starter

  • Members
  • 5 posts
  • Local time:12:48 PM

Posted 17 May 2015 - 08:00 PM

Reset home page by typing in the URL does not help.


As soon as I apply it, the home page is reset. Look like some helper running in the background.


The following is the RKill.exe report:


Rkill 2.7.0 by Lawrence Abrams (Grinler)
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:

Program started at: 05/17/2015 08:54:24 PM in x64 mode.
Windows Version: Windows 7 Ultimate Service Pack 1

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * C:\Windows\SysWOW64\HsMgr.exe (PID: 5420) [WD-HEUR]
 * C:\Windows\system\HsMgr64.exe (PID: 5444) [WD-HEUR]

2 proccesses terminated!

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * No issues found.

Checking Windows Service Integrity:

 * No issues found.

Searching for Missing Digital Signatures:

 * No issues found.

Checking HOSTS File:

 * HOSTS file entries found:

  2 out of 3 HOSTS entries shown.
  Please review HOSTS file for further entries.

Program finished at: 05/17/2015 08:54:43 PM
Execution time: 0 hours(s), 0 minute(s), and 18 seconds(s)


The following is the AdwCleaner So report:


# AdwCleaner v3.302 - Report created 02/08/2014 at 09:48:27
# Updated 30/07/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : ckw8 - WONG8
# Running from : C:\Users\ck\Downloads\Cleanup Tools\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : nvsvc

***** [ Files / Folders ] *****

Folder Deleted : C:\Users\ck\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\ck\AppData\LocalLow\Search Settings
Folder Deleted : C:\Users\ck\AppData\LocalLow\Vuze_Remote
Folder Deleted : C:\Users\ckw8\AppData\Local\AppsHat Mobile Apps
Folder Deleted : C:\Users\ckw8\AppData\Local\Bundled software uninstaller
Folder Deleted : C:\Users\ckw8\AppData\Local\Conduit
Folder Deleted : C:\Users\ckw8\AppData\Local\Minibar
Folder Deleted : C:\Users\ckw8\AppData\Local\webplayer
Folder Deleted : C:\Users\ckw8\AppData\Roaming\NCH Software
File Deleted : C:\Windows\System32\nvvsvc.exe

***** [ Scheduled Tasks ] *****

***** [ Shortcuts ] *****

Shortcut Disinfected : C:\Users\ckw8\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppsHat\Uninstall.lnk

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchSettings_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\SearchSettings_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{539F76FD-084E-4858-86D5-62F02F54AE86}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{60EACC1A-33FA-443D-9846-17B28E2C9BDB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E30ED111-BD63-48C2-A6CB-AB3C9FFFB07C}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{F13D3582-1359-4F8F-9A48-EF3AE9F5701C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E30ED111-BD63-48C2-A6CB-AB3C9FFFB07C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{090CE759-19B2-4D1B-A3F2-C2122C6994A1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C9A73ECD-81CB-4E0D-AC49-AAA0C8D04F01}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{539F76FD-084E-4858-86D5-62F02F54AE86}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{BA14329E-9550-4989-B3F2-9732E92D17CC}]
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : HKCU\Software\Webplayer
Key Deleted : HKCU\Software\AppDataLow\Software\Vuze_Remote
Key Deleted : HKLM\Software\Minibar
Key Deleted : HKLM\Software\Vuze_Remote
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\AppsHat Mobile Apps
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vuze_Remote Toolbar
Key Deleted : [x64] HKLM\SOFTWARE\systweak

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17207

-\\ Mozilla Firefox v31.0 (x86 en-US)

[ File : C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\rwz8ly6g.default\prefs.js ]

[ File : C:\Users\ck\AppData\Roaming\Mozilla\Firefox\Profiles\0ieej9va.default\prefs.js ]

Line Deleted : user_pref("extensions.fvd_single.surfcanyon.ramp.start_time", "1394153369343");

[ File : C:\Users\ckw8\AppData\Roaming\Mozilla\Firefox\Profiles\r3v00sv6.default-1397730715960\prefs.js ]

-\\ Google Chrome v

[ File : C:\Users\ck\AppData\Local\Google\Chrome\User Data\Default\preferences ]

[ File : C:\Users\ckw8\AppData\Local\Google\Chrome\User Data\Default\preferences ]



#7 noknojon


  • Banned
  • 10,871 posts
  • Gender:Not Telling
  • Local time:02:48 AM

Posted 17 May 2015 - 10:24 PM

These are the Microsoft directions to Reset Internet Explorer 11

When Malwarebytes Anti-Malware has finished, please follow these directions, it seems that a minor infection is "playing games" with us .......

To Fully reset Internet Explorer settings
  1. Close all Internet Explorer windows that are currently open.

  2. Open the desktop, and then tap or click the Internet Explorer icon on the taskbar. Changing your settings will affect both Internet Explorer and Internet Explorer for the desktop.

  3. Click the Tools button f2d3a394-a4c3-4747-989e-cf3f6b782b2f_43., and then click Internet options.
  4. Click on the Advanced tab, and then tap click on Reset.

  5. In the Reset Internet Explorer Settings dialog box, tap click Reset.

  6. When Internet Explorer finishes applying default settings, click Close, and then tap or click OK.

  7. NOTE : You will need to restart your PC for these changes to take effect.

Now, try the above method to select a Home Page.


To help with any bad programs that may be left, please follow these directions also.

Please download MiniToolBox  to desktop to run it.
 Checkmark the following boxes:

  • List content of Hosts
  • Flush DNS
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
 Click Go and Copy / Paste the result. (Result.txt)



Download Screen317Security Check from Here or Here and save it to your Desktop.

  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt
  • Please Copy/Paste the contents of that document.

Note 1:: If any security program requests permission to access the Internet, allow it to
Note 2. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message, (or similar) restart computer and Security Check should run


Thank You -

#8 ckw888

  • Topic Starter

  • Members
  • 5 posts
  • Local time:12:48 PM

Posted 04 June 2015 - 05:36 AM

Yes. It works. I also notice that the home icon is changed. It seems the home button was overlaid with some other object which also trap the Control-H. Thanks a lot.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users